Home  /  Resources  /  About RedSecLabs
About us

About RedSecLabs

A London-based cybersecurity consultancy. CREST member and PCI DSS QSA company, trusted by regulated organisations across financial services, healthcare and the wider public and private sectors.

CREST MemberPCI DSS QSAEstablished 2023 · London
What drives us

Mission & vision

The principles and ambitions that shape every engagement we deliver.

Our mission

Pragmatic, evidence-based cybersecurity consulting that helps regulated organisations meet their compliance obligations and substantively improve their resilience, not just produce paperwork that passes an audit.

Our vision

To be the firm regulated organisations call when the stakes are real: when an incident is unfolding, when a board needs risk in plain language, when a regulator is asking hard questions. Long relationships, not transactional engagements.

By the numbers

What makes RedSecLabs different

A senior-led practice with a portfolio that crosses sectors and jurisdictions.

60+
Regulated clients across financial services, retail and technology
75%
Recurring engagement rate, year over year
250+
Security projects delivered since 2023
100%
Senior consultants only, no junior pass-through
Leadership

Meet the founder

Rafay Baloch
Founder & CEO
Building cybersecurity expertise from the field, not from textbooks.

Rafay first gained global recognition during university after uncovering major vulnerabilities across leading platforms and browsers. He has since worked with global organisations and technology vendors, including Microsoft, Apple and Google, responsibly disclosing flaws that affected hundreds of millions of users. His research has been cited in books, academic curricula and industry conferences, and he has spoken at Black Hat, BSides and other leading venues.

“The consulting industry is full of people who can produce reports. We built RedSecLabs to be the firm clients actually call when something matters: a regulator asking hard questions, an incident unfolding at 2am, a board needing risk in plain language.”

Rafay Baloch, Founder & CEO

Rafay leads the firm from London. He still does technical work alongside the consulting team and writes for the RedSecLabs research publication, the combination of practitioner experience and business leadership that RedSecLabs was built around.

How we work

Our core values

The principles that shape every engagement, every report and every client relationship.

01

Security-first mindset

We prioritise security in everything we touch: our work, our advice and the way we handle client data. Threat modelling is how we think, not an extra service.

02

Independence

We sell consulting, not software licences. Our recommendations are vendor-neutral and based on what your environment actually needs, not what is profitable for us to resell.

03

Plain English

Findings explained without jargon. Reports the board can read. Risk articulated in terms that translate to business decisions, not just technical severity ratings.

04

Senior consultants only

Every engagement is led by a senior consultant who has done the work before. No junior pass-through, no offshore relabel, no name bait-and-switch.

05

Pragmatism over theatre

Compliance that produces real improvement, not just audit-ready paperwork. Pentests that find what attackers would find, not noise that fills page count.

06

Long client relationships

Most clients return year on year. We optimise for the long relationship over the transaction, which means honest advice even when it loses us a sale.

Credentials

Established credentials, independently verified

RedSecLabs holds the accreditations that regulated buyers verify. We do not claim qualifications we do not hold.

CREST Member

CREST-accredited for high-assurance penetration testing, recognised globally as the standard for offensive security.

PCI DSS QSA

Qualified Security Assessor methodology for PCI DSS compliance work across the UK, US and Middle East.

PCI ASV (via partner)

An ASV partnership authorised to perform the external vulnerability scans PCI DSS Requirement 11.3.2 demands.

Established 2023

Headquartered in the United Kingdom, with delivery teams covering UK, EU, US and Middle East engagements.

Working with

Strategic partners

We work alongside specialist partners where complementary expertise serves the client better.

Zettamight
Work Generations

Let’s talk about your security programme

Book a 30-minute scoping call with our management team. No obligation, same-day reply, and a fixed fee within 48 hours.

SOC 2 Type I & Type II, fixed-feeScope, timeline and quote back within 24 hours Get a fixed-fee quote Book a scoping call